LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

Package(s):cherokee CVE #(s):
Created:November 1, 2004 Updated:November 2, 2004
Description: Florian Schilhabel from the Gentoo Linux Security Audit Team found a format string vulnerability in the cherokee_logger_ncsa_write_string() function. Using a specially crafted URL when authenticating via auth_pam, a malicious user may be able to crash the server or execute arbitrary code on the target machine with permissions of the user running Cherokee.
Alerts:
Gentoo 200411-02 2004-11-01

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.